An unusually disciplined local security scanner: SHA-pinned engines, zero scan-time egress, no telemetry, redacted secrets, a three-state honest evidence model, and rare candor about its own limits (narrow native rules, AI-drafted compliance mappings, heuristic prompt-injection detection). Well suited to agent-driven scan-fix-rescan security loops; not a substitute for deep audits, runtime testing, or compliance certification. MIT licensed, solo-maintained by Synvoya, with independent security review actively solicited.
Security and permissions
18/20
Read the FMRS scoring method →